Security & data protection

You are trusting us with your members' personal information and their payments. Here is what is in place today, what we are building next, and how we handle data, told straight.

In place today

Encryption in transit

Every page and API request runs over HTTPS/TLS, so member and payment data is encrypted between the browser and our servers.

PCI-compliant payments

Card payments are processed by certified providers such as Stripe. Card numbers never touch our database.

Role-based access

You decide who sees what. Confidential fields, financials, and admin tools are limited to the roles you assign.

Backups & US hosting

Your data is backed up on a regular schedule and hosted in United States data centers.

Data retention & export

We keep your data for as long as you are a customer and make it available for export. After termination it is exported on request, then deleted in the ordinary course.

Subprocessors & DPA

We use a small set of vetted subprocessors (hosting, payments, email). A current list and a Data Processing Addendum are available on request.

Incident response

If a security incident affects your data, we investigate promptly and notify affected customers without undue delay.

Responsible disclosure

Found a vulnerability? Email us and we will investigate and respond quickly.

On our roadmap

We would rather be honest than overstate. These are not in place yet; they are what we are actively working toward. Ask us where each one stands and expected timelines.

SOC 2 Type II
A formal third-party audit of our controls.
Third-party penetration testing
Regular external testing with a summary available under NDA.
MFA and SSO / SAML
Multi-factor login and single sign-on for staff and members.
Encryption at rest
Database-level encryption in addition to encryption in transit.
Published RPO / RTO
Documented recovery-point and recovery-time targets, with backup frequency.

AI & your data

Our AI assistant is designed to help your staff, not to mine your members. When you use an AI feature, only the specific content needed to answer that request is sent to our AI provider.

We do not sell member data, and we do not permit your member data to be used to train third-party AI models. AI processing is covered by the same Data Processing Addendum as the rest of the platform, and you can turn AI features off for your account.

Want the specifics, including which provider we use and the exact data flow? Ask us and we will walk your team through it.

Security questions from your board?

Send us your security questionnaire or ask for our DPA and subprocessor list. We answer straight.

Talk to us